About the Team OpenAI builds powerful AI systems like ChatGPT, the OpenAI API, and enterprise products that serve millions of users across the globe. As we scale, securing our infrastructure, protecting sensitive data, and meeting global compliance standards are essential to our success and societal impact. Security at OpenAI is a cross-cutting function that spans infrastructure, applied engineering, legal, policy, and product. Technical Program Managers (TPMs) play a critical leadership role in aligning teams and delivering execution at scale and this role will be foundational in shaping how we secure OpenAI’s systems, users, and commitments. About the Role We’re seeking a Senior Technical Program Manager to drive cross-functional security, privacy, IT and compliance initiatives at the intersection of infrastructure, product, and policy. You will execute complex programs that reduce internal data access, prevent misuse, and ship security capabilities. You will focus your efforts on the most critical initiatives within Security, crossing the spectrum of insider threat, information security, physical security, and information technology challenges. This role is deeply technical and execution-focused. It requires a structured operator who thrives in ambiguity, partners effectively across boundaries, and applies principled judgment to scale trust, governance, and security across OpenAI’s systems and products. In this role, you will: Drive execution of critical security and compliance programs such as vulnerability management, merger and acquisition security and integration, infrastructure hardening, and datacenter security management. You will need to deeply collaborate on technical architecture and resolve technical problems in partnership with engineering. Partner with IT, Infrastructure, Application, Legal, Privacy, and Security teams to build scalable programs, and deliver critical security outcomes across multiple disciplines, including insider threat, information
Jobs in United States
Vulnerability Management Engineer in United States
35 active opportunities · Updated October 2026
Showing
15 jobs
Explore current vulnerability management engineer jobs across United States. Filter by work mode, employment type, experience, department, date posted and distance.
From $113.4K/yr
Zscaler (NASDAQ: ZS) accelerates digital transformation so customers can be more agile, efficient, resilient, and secure. The Zscaler Zero Trust Exchange™️ platform protects thousands of customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location. Distributed across 160+ public exchanges globally and thousands of private exchanges at the edge, the SASE-based Zero Trust Exchange is the world’s largest in-line cloud security platform. We believe the future of work is Human + AI and are building an AI-native enterprise where human potential is amplified by machine intelligence to solve the world’s hardest security challenges. Driven by deep customer obsession, we are committed to the mission, outcome, and to each other. We bring these commitments to life through three core behaviors: ownership and collaboration, trust through outcomes and impact, and a challenge culture with ongoing feedback. Ready to make an impact at the company pioneering security transformation in the AI era? Join us at Zscaler. About the Role We are looking for a Product Sales Account Executive to join our Sales and Go-to-Market team. This role can be based in any major city within San Francisco, Rockies or OH Valley area, reporting to the Director, SecOps. You will support a specific region, acting as the primary specialist to drive revenue growth within the security operations product suite, including unified vulnerability management, deception and threat hunting. You will lead the charge in demonstrating the power of cloud transformation to cement our position as a global leader in cloud security. What you’ll do (Role Expectations) Serve as the primary specialist for customers, partners, and internal teams to drive revenue growth across the security operations product portfolio Partner with domain-expert solution engineers to capture customer requirements and craft compelling value propositions that close complex business deals Own the regio
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the Role We are looking for a highly skilled PSIRT Engineer to lead the vulnerability response program for Replit’s cloud-native AI platform. You will own the lifecycle of security vulnerabilities affecting our products and services—from intake to validation, remediation coordination, and public disclosure. This role requires strong technical ability to reproduce vulnerabilities , deep understanding of web/app/cloud exploit classes, and experience operating bug bounty and coordinated disclosure programs. You will work closely with Engineering, Cloud Security, SecOps, SRE, and IT teams to ensure vulnerabilities are fixed quickly and communicated responsibly. What You’ll Do Vulnerability Intake, Triage & Validation Manage intake from bug bounty platforms (HackerOne preferred), customer reports, automated scanners, pentest reports, and coordinated disclosure channels. Independently validate, reproduce, severity-score, and document findings. Identify duplicates and maintain a clean vulnerability records pipeline. Assess relevance and exploitability using OWASP, cloud misconfiguration patterns, and identity/authentication/authorization risks (Oauth, OIDC). Remediation Coordination & SLA Management Work with Engineering, SecOps, IT, SRE, and Cloud Security to confirm product impact and drive remediation. Provide detailed reproduction steps, proof-of-concepts, and technical analyses. Track SLAs, remediation progress, regression testing, and systemic improvements. Support SOC 2, ISO 27001, and pentest evidence needs as part of vulnerability lifecycle governance. Bug Bounty & Vulnerability Disclosure Program Management Design and evolve the bug bounty program, including scope, rules, and reward structures. Man
About the Team The Release Engineer team is responsible for building and maintaining the systems that power software delivery—from CI/CD pipelines and artifact management to release automation and fleet telemetry. We ensure software across bootloaders, firmware, operating systems, and cloud services is built reproducibly, validated rigorously, and released safely at scale. About the Role As a Release Engineer, you’ll design, build, and operate release infrastructure that enables reliable, secure, and traceable software delivery across complex multi-component systems. You’ll partner closely with embedded, cloud, and QA teams to ensure that every build—from development to OTA deployment—is fast, verifiable, and production-ready. We’re looking for engineers who take pride in automation, build reproducibility, and system reliability—and who enjoy building the connective tissue that allows hardware and software to ship together seamlessly. This role is based in San Francisco, CA. We use a hybrid work model of four days in the office per week and offer relocation assistance to new employees. In this role, you will: Design and operate CI/CD pipelines for multi-component builds (bootloader, firmware, OS images, backend, companion apps) using hermetic toolchains. Define versioning and branching strategies; automate promotions, changelogs, and artifact retention. Integrate unit, integration, and hardware-in-the-loop (HIL) test results; quarantine flaky tests, auto-bisect failures, and block unsafe promotions. Build A/B OTA update flows with verity and health checks; run staged rollouts and canaries; implement safe rollback and roll-forward strategies. Implement code signing for binaries and firmware, generate SBOMs, run vulnerability scanning, and attach build attestations and provenance. Manage dashboards and alerts for build health, promotion latency, failure rates, and fleet update telemetry. You might thrive in this role if you: Have experience building and operating buil
Senior Systems Engineer (Flight Crew Operations Integrator) Company: The Boeing Company Boeing Defense, Space & Security (BDS) is seeking a Senior Systems Engineer (Level 5) to support the Phantom Works organization in Hazelwood, MO . The successful candidates will develop equipment and escape/crew station system integration concepts and other design methods to provide and coordinate product definition for Integrated Product Teams, various engineering functions, production operations, qualification/flight testing, suppliers and external customers throughout the product lifecycle. Position Responsibilities Applies an interdisciplinary, collaborative approach to lead activities to plan, design, develop and verify complex lifecycle balanced system of systems and system solutions. Leads others to evaluate customer/operational needs to define system performance requirements, integrate technical parameters and assure compatibility of all physical, functional and program interfaces. Leads analyses to optimize total system of systems and/or system architecture. Leads analyses for affordability, safety, reliability, maintainability, testability, human systems integration, survivability, vulnerability, susceptibility, system security, regulatory, certification, product assurance and other specialties quality factors into a preferred configuration to ensure mission success. Leads, develops, maintains and identifies improvements the planning, organization, implementation and monitoring of requirements management processes, tools, risk, issues, opportunity management and technology readiness assessment processes. Travel may be required up to 10% of the time; Domestically and/or interna
GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster. The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software. * Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab. An overview of this role As a Senior Product Manager , you will own GitLab's Secret Detection offering and the Vulnerability Research function that produces the detection content across security products. Secret Detection is one of the highest-signal, highest-volume security capabilities on the platform. Leaked credentials are the most common initial access vector in real breaches, and as AI agents write, commit, and configure more of the software, the surface area for exposed secrets grows faster than the number of humans watching it. You will own the full loop: detect a secret with high precision, tell the customer whether it i
The Engineering Lead Analyst – SonarQube & Code Quality Engineering is a senior-level engineering role responsible for leading static code analysis, automated code quality governance, security vulnerability remediation, and AI-augmented developer enablement across enterprise software delivery pipelines. In this role, you will champion software reliability, maintainability, clean-coding standards, and automated quality gates. You will partner with development teams, system architects, and platform engineering to integrate and manage enterprise-scale code quality platforms (such as SonarQube) both on-premises and in cloud/SaaS environments. Additionally, you will drive modern engineering practices by embedding Behavior-Driven Development (BDD) within your own software delivery and leveraging Agentic AI workers and Model Context Protocol (MCP) architectures to optimize developer experience, streamline code governance, and boost engineering velocity. Key Responsibilities 1. Code Quality & Static Analysis Platform Ownership Lead the architecture, deployment, administration, and continuous enhancement of enterprise Static Application Security Testing (SAST) and Code Quality platforms (e.g., SonarQube , DeepSource, Codacy, Semgrep). Configure, calibrate, and enforce automated Quality Gates, code rulesets, technical debt calculation models, and code-coverage baselines across multi-language enterprise repositories. Oversee version upgrades, patching, high availability, and operational maintenance for on-premises and SaaS/cloud-hosted code quality infrastructure. 2. CI/CD & Pipeline Integration <li style=
About the Team Our Safety Systems team is at the forefront of OpenAI's mission to build and deploy safe AGI, driving our commitment to AI safety and fostering a culture of trust and transparency. Within Safety Systems, the Model Policy team aligns model behavior with desired human values and norms. We co-design policy with models and for models by driving rapid policy taxonomy iteration based on data and defining evaluation criteria for foundational models’ ability to reason about safety. About the Role Frontier AI systems are rapidly expanding what is possible in cybersecurity and software engineering. These capabilities create major defensive opportunities, but they also raise serious dual-use and misuse risks across areas such as malware development, exploit discovery, vulnerability chaining, credential abuse, cyber intrusion, and autonomous offensive operations. In this role, you will help define how OpenAI’s models should behave in high-risk cybersecurity contexts. You will develop policy frameworks, threat models, taxonomies, evaluations, and behavioral specifications that guide model behavior across training, deployment, and monitoring systems. This role sits at the intersection of cybersecurity, AI safety, threat modeling, evaluation science, and policy implementation. You will work closely with research, engineering, safety training, preparedness, and product teams to build policies that are technically grounded, measurable, enforceable, and responsive to real-world cyber risk. Your Responsibilities: Design and maintain model policies for cybersecurity and frontier-risk domains, especially dual-use and high-risk cyber capabilities. Translate cybersecurity threat models into clear behavioral specifications, evaluation criteria, grading guidance, and system-level mitigations. Define practical boundaries between legitimate security research, defensive workflows, and assistance that could materially enable harmful activity. Build policy artifacts that support i
Become a part of our caring community Do you thrive on designing secure, enterprise-scale solutions that protect critical systems, data, and networks? As a Lead Security Architect in Humana, you will play a key role in shaping the security blueprint for the organization by aligning security architecture and infrastructure with enterprise business and technology priorities. In this role, you will partner with EIP and business leaders to assess emerging threats, identify architectural gaps, and design forward-looking security solutions that strengthen Humana's overall security posture. You will also lead security assessments, vulnerability analysis, and product security reviews while helping develop innovative testing approaches and mitigation strategies for evolving risks. This is a high-impact opportunity to influence enterprise architecture, guide secure technology design, and help protect the business through strategic, modern security architecture. The Lead Security Architect engages with relevant EIP stakeholders to identify current and emerging security threats and works to design security architecture elements to mitigate threats as they emerge. Additionally, the role actively works to identify gaps within existing EIP reference architecture and designs updates to impacted security architecture elements to mitigate emerging threats. Performs and oversees efforts to conduct vulnerability testing, risk analysis, and security assessments of relevant enterprise / EIP infrastructure. Ensures EIP and Humana stakeholder security requirements are necessary to protect Humana's business functions and are adequately addressed in all aspects of enterprise architecture. The Lead Security Architect role is aligned to a segment (line of business) to proactively discover security issues during solution design and prevent vulnerabilities during development.
Senior Offensive Cybersecurity Test Analyst Company: The Boeing Company The Boeing Company is seeking a Senior Offensive Cybersecurity Test Analyst to support the Boeing Test & Evaluation (BT&E) cyber test capability. The selected applicant will join a highly technical Test & Evaluation team building an offensive cyber test capability in Berkeley, MO . This position will be providing testing services to Boeing Defense Space & Security (BDS) portfolio. The primary responsibilities will include Product Security (Cyber) test planning, integration, and execution, mission-based risk assessments, vulnerability assessments, and penetration tests. The selected applicant will become a Berkeley team member trained across the broader BT&E Product Security Capability team. Position Responsibilities: Lead execution of penetration tests to identify, exploit, and assess a target system’s vulnerabilities in a threat-representative manner on embedded systems and IP-based networks Subject Matter Expert for emulating advanced cyber adversary (advanced persistent threats) tactics, techniques and procedures (TTPs) Lead controlled attack simulations that test the effectiveness of a blue team and its capabilities to detect, block, and mitigate attacks and breaches</span
Software Systems Engineer (Associate or Experienced) Company: The Boeing Company The Boeing Company has an exciting opportunity for a Software Systems Engineer to join the SATCOM Mission Planning Software Engineering team in Seal Beach, CA. Our teams are currently hiring for a broad range of experience levels including; Associate and Experienced Software Engineers. The Satellite Communication (SATCOM) Mission Planning team is a critical part of the U.S. military’s nuclear command, control, and communications (NC3) network, providing nuclear-survivable connectivity. Our team develops software tools and services for advanced satellite and ground systems. This role offers the opportunity to work in a fast-paced development environment using modern, scalable technology and tools. Our team works in an Agile and CI/CD environment with automated testing, vulnerability scanning, and quality scanning capabilities. Position Responsibilities: Develops and maintains requirements, architecture, algorithms, interfaces, and designs for high-performance APIs between front-end and back-end software services Supports software development activities in an Agile environment using DevSecOps methodologies, including integration of completed software components into a fully functional software system Supports the development of critical features and support the full development lifecycle from design through deployment Builds, architects, and consumes APIs and backend services as part of the platform ecosystem, with an emphasis on automation, testing, and security Conducts code reviews to maintain code quality, enforce best practices, and ensure compliance wit
Software Engineer (Associate or Experienced) Company: The Boeing Company The Boeing Company has an exciting opportunity for a Software Engineer to join the SATCOM Mission Planning Software Engineering team in Colorado Springs, CO. Our teams are currently hiring for a broad range of experience levels including; Associate and Experienced Software Engineers. The Satellite Communication (SATCOM) Mission Planning team is a critical part of the U.S. military’s nuclear command, control, and communications (NC3) network, providing nuclear-survivable connectivity. Our team develops software tools and services for advanced satellite and ground systems. This role offers the opportunity to work in a fast-paced development environment using modern, scalable technology and tools. Our team works in an Agile and CI/CD environment with automated testing, vulnerability scanning, and quality scanning capabilities. Position Responsibilities: Develops and maintains requirements, architecture, algorithms, interfaces, and designs for high-performance APIs between front-end and back-end software services Supports software development activities in an Agile environment using DevSecOps methodologies, including integration of completed software components into a fully functional software system Supports the development of critical features and support the full development lifecycle from design through deployment Builds, architects, and consumes APIs and backend services as part of the platform ecosystem, with an emphasis on automation, testing, and security Conducts code reviews to maintain code quality, enforce best practices, and ensure compliance with establis
About the team The AI Deployment Engineering team is responsible for helping developers and enterprises safely and effectively deploy OpenAI technologies in production. We act as trusted technical advisors and thought partners for customers, working side by side with their teams to identify high-value use cases, design practical architectures, and move from prototype to durable deployment. Cybersecurity is one of the most urgent domains where AI can help. Security teams are under pressure to reason across code, logs, infrastructure, tickets, alerts, and vulnerability data faster than ever. As frontier models become more capable, organizations need deep technical guidance on how to evaluate, validate, and safely deploy AI systems in security-critical workflows. About the role We are looking for a Cyber AI Deployment Engineer to partner with customers and help them apply OpenAI models, APIs, Codex, and agentic workflows to real cybersecurity use cases. You will work with CISOs, security executives, application security leaders, SOC teams, security engineering teams, and hands-on practitioners to identify where AI can create measurable security outcomes. This is a customer-facing technical role for someone who can move fluidly between executive strategy, practitioner-level cyber depth, and hands-on solution design. You will help customers evaluate and deploy workflows such as secure code review, vulnerability triage, threat modeling, remediation, SOC and incident response workflows, detection engineering, cloud security, GRC automation, and security validation. You will collaborate closely with Sales, Solutions Engineering, Product, Engineering, Research, and Security to turn customer needs into safe deployment patterns, reusable field assets, and product feedback. This role is based in our San Francisco HQ. We offer relocation support to new employees. In this role, you will: Deeply embed with strategic customers as the technical lead for AI-enabled cybersecurity work
Software Systems Engineer (Associate or Experienced) Company: The Boeing Company The Boeing Company has an exciting opportunity for a Software Systems Engineer to join the Satellite Communication (SATCOM) Mission Planning Software Engineering team in Colorado Springs, CO. This position will support the Boeing Defense, Space & Security (BDS) Satellite Systems Software Engineering organization. Our teams are currently hiring for a broad range of experience levels including; Associate and Experienced Software Engineers. The Satellite Communication (SATCOM) program is a critical part of the U.S. military’s nuclear command, control, and communications (NC3) network, providing nuclear-survivable connectivity. Our team develops software tools and services for advanced satellite and ground systems. This role offers the opportunity to work in a fast-paced development environment using modern, scalable technology and tools. Our team works in an Agile and CI/CD environment with automated testing, vulnerability scanning, and quality scanning capabilities. Position Responsibilities: Develops and maintains requirements, architecture, algorithms, interfaces, and designs for high-performance APIs between front-end and back-end software services Supports software development activities in an Agile environment using DevSecOps methodologies, including integration of completed software components into a fully functional software system Supports the development of critical features and support the full development lifecycle from design through deployment Builds, architects, and consumes APIs and backend services as part of the platform ecosystem, with an emphasis on
Our Purpose Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we’re helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential. Title and Summary Data Scientist What is the opportunity? We are seeking a highly skilled and motivated Data Scientist to join our Cyber Analytics team within the Security Solutions Data Science organization. This role is critical to driving advanced analytics initiatives, improving fraud detection capabilities, and supporting strategic decision-making across cybersecurity and payment fraud domains. What will you do? • Gain subject matter knowledge on web application security, commonly exploited cyber vulnerabilities, and methods of online and payment card fraud including the common points of purchase for compromised cards. • Build, develop, and maintain innovative data-driven analytical solutions, including predictive models and machine learning algorithms, on large volumes of data to support analytics and reporting needs across products, markets, and services. • Competently handle large datasets, sifting for patterns and trends and translating those insights into technical rules and solutions. • Combine cybersecurity and transaction data into new and insightful views of fraud and vulnerability across the Mastercard network. • Collaborate with cross-functional teams including product, engineering, and operations to understand product, usage, and data pipelines as well as delivering scalable solutions. • T
Other cities to consider
More places hiring for this role
Get new vulnerability management engineer jobs in United States by email
Daily job updates · Unsubscribe anytime